🔧 AI Nachrichten Major AI platforms go down in unprecedented simultaneous outage(03.09.2026 um 17:34 Uhr)
🔧 AI Nachrichten ChatGPT, Claude, and Grok Down? Users Report Widespread Outages(03.09.2026 um 19:14 Uhr)
🔧 AI Nachrichten OpenAI Launches GPT-6 Astra, Says We May Have Entered the AGI Era(03.09.2026 um 22:08 Uhr)
🔧 AI Nachrichten Claude Comes to CarPlay as Fifth Major AI Chatbot App(05.09.2026 um 05:31 Uhr)
🔧 AI Nachrichten OpenAI’s GPT-6 Astra Is AGI, Says NVIDIA CEO Jensen Huang(07.09.2026 um 06:31 Uhr)
🔧 AI Nachrichten Blame AI companies for Mac mini and Mac Studio shortage(31.08.2026 um 10:32 Uhr)
🔧 AI Nachrichten Major AI platforms go down in unprecedented simultaneous outage(03.09.2026 um 17:34 Uhr)
🔧 AI Nachrichten ChatGPT, Claude, and Grok Down? Users Report Widespread Outages(03.09.2026 um 19:14 Uhr)
🔧 AI Nachrichten OpenAI Launches GPT-6 Astra, Says We May Have Entered the AGI Era(03.09.2026 um 22:08 Uhr)
🔧 AI Nachrichten Claude Comes to CarPlay as Fifth Major AI Chatbot App(05.09.2026 um 05:31 Uhr)
🔧 AI Nachrichten OpenAI’s GPT-6 Astra Is AGI, Says NVIDIA CEO Jensen Huang(07.09.2026 um 06:31 Uhr)
🔧 AI Nachrichten Blame AI companies for Mac mini and Mac Studio shortage(31.08.2026 um 10:32 Uhr)
1 Tag Serie
📰 IT Security Nachrichten 🕛 kürzlich 7 Min Lesezeit SECURITY-FEED
0

Risky Business: The Fifth Element

↗ Quelle (feedproxy.google.com)
🗣️ Stimme:

Last month, I talked about the elegant beauty in offloading parts of your risk portfolio in function and how their teams are structured. Instead of hiring dozens of people to build and maintain multiple systems, CISOs will shift to focus on the data that powers the business and how it flows through and interacts with these outsourced relationships. 


And yes, I am going so far as to say this shift is inevitable, because it’s being driven by some pretty clear economic pressures:


Talent scarcity 


It’s well-known that there are a lot of open job reqs in cybersecurity. I mean a lot—more than a million today. And according to Center for Cyber Safety and Education’s 2017 Global Information Security Workforce Study, there may be as many as 1.8 million open jobs in the field by 2022.  


In this market, finding the right person can take months. You either have to poach them from another company or develop them yourself. Development means trial by fire. I don’t know about you, but I don’t want trial by fire. And if you do steal a great hire from another company, the cost-benefit analysis is such that you’re basically being driven to a vendor anyway, simply because the salary pressure makes it more cost-effective. 


There are also specific areas of risk that require hard-to-find skills, which only exacerbate this phenomenon. Try to hire a great DDoS or application security specialist and you’ll see what I mean. It’s no coincidence that the jobs with the highest degree of talent scarcity are the first ones being outsourced. 


The reality of the situation is those specialists increasingly work for … guess who? Security-as-a-service companies. They’re the only ones that can afford that level of talent, and having that talent is their core differentiator. 


Economies of scale


Most CISOs will never be able to address all of a company’s risk anyway. They’ll never have enough resources to truly cover all of them. 


So take the example of application security, one of those unique skillsets that’s so difficult and expensive to hire for. In this environment, outsourcing application security scanning to a vendor just makes too much sense. 


Why? Because of economies of scale. With its crack team of top-tier analysts, the Sec-aaS vendor can provide a complete assessment of the company’s risk footprint in a few weeks. 


If a company were to hire those skills in-house, they would make a similar or even larger investment and still wouldn’t have that kind of scale. Your in-house expert, as brilliant as they may be, would not be able to provide an understanding of the entire footprint along with the details of what needs to be done within a few weeks. The scale is just too big. 


Taking this to the next level, outsourced vendors are also finding ways to automate these processes, creating platforms that apply the experience of their entire team of experts for the customer’s benefit. 


This means they can provide analysis much more quickly, which means you can start doing mitigations much more quickly, which means your window of exposure is much smaller, which ultimately means the benefit for mitigating risk is much more effective. 


Companies can expect similar benefits across Sec-aaS categories. If you outsource WAF, you’re no longer focused on implementing that control mechanism. With the right DDoS vendor, your traffic is getting scrubbed all the time. The customer no longer needs to be concerned with those controls. 


Like today’s cloud and SaaS platforms, these are cost-effective models. But the benefits of using a security-as-a-service vendor is not only transferring the risk and saving money. Instead of somebody who’s concentrating on learning DDoS, you can hire people who understand the company, its industry and its own unique characteristics. You can give them the time to become a true business partner, working directly with business groups to understand the company’s assets and align security to the business. 


And for CISOs, shift your focus to understanding your own data flows and managing your consumption-based security services with pinpoint precision. Solve challenges for your own company that have not already been solved. 


Ultimately this movement is going to transform the security industry. Over the next few years, we’ll see a world of security that will be more cost-effective and more focused on user experience. The business will have security ingrained within it, rather than wrapped around it. And removing that friction will allow the business to accelerate. 


As for trying to solve DDoS? Application security? Firewalls? Don’t try to solve it yourself. Go ahead and let the fifth element of Sec-aaS providers commoditize where they can. We’ll all be better off.












and serves as a worldwide security evangelist for the company. Previously, he was a Security Product Manager at F5, specializing in network security Governance, Risk, and Compliance (GRC). He joined F5 in 2010 as a Security Architect and was responsible for designing F5’s current Information Security Management System. Preston has a proven track record building out Information Security Management Systems with Security Service Oriented Architectures (SSOA), enabling enhanced integration, automation, and simplified management. Before joining F5, he was Director of information Security at social media provider Demand Media where he built out the information security team. Preston’s career began 18 years ago when he served as a security analyst performing operational security (OPSEC) audits for the U.S. Air Force. He currently holds CISSP, CISA, CISM, and CRISC security and professional certifications.
Previous Columns by Preston Hogue:


view counter

view counter

sponsored links



Tags:


Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf feedproxy.google.com.
↗ Original-Artikel auf feedproxy.google.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
3 Quellen
GPT-6 Astra Release Today? OpenAI’s Next Major AI Model Is Almost Here
1 Quelle
Apple accuses OpenAI of destroying evidence as trade-secrets fight intensifies
1 Quelle
Major AI platforms go down in unprecedented simultaneous outage